Hiding Mr.Fishit using FU (rootkit) menu

Shout-Out

User Tag List

Page 1 of 2 12 LastLast
Results 1 to 15 of 29
  1. #1
    iruleatants's Avatar Active Member
    Reputation
    16
    Join Date
    Apr 2008
    Posts
    73
    Thanks G/R
    2/2
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Hiding Mr.Fishit using FU (rootkit)

    Firstly, This was created to assist people who bot with Mr.Fishit in hiding their process, and further more making Wow.exe from being able to detect it!!

    Step one.

    Download the rootkit from rootkit.com
    (Easy right?) The problem is, most Anti-virus's will detect this as a Trojan. Because, technically it is. This is a good Trojan though, because it will hide what you want, and not do anything unwanted. So, most likely you will need to create an exception for your antivirus so it wont delete your precious files.

    Step two.

    So, you downloaded the rar, and now your wondering what to do.

    Extract the rar file(You only need the files inside the folder EXE to save you more time, and specifically, "msdirectx.sys" and "FU.exe") to anywhere you want. After you have extracted the files, take the files "msdirectx.sys" and "FU.exe" and move them directly into MR.Fishits directory. This is what it should look like (Excluding the hidemeplease.exe name, which will be whatever you named mr.fishit, and the Bat file)



    Step Three

    Download the attached file, and extract it to your Mr.Fishit Directory. Right click on it and Edit. in the notepad window that opens, you ill see this


    Start HIDETHISPLEASE.exe
    FOR /F "tokens=3 delims=:" %%a in ('FU -pl 100 ^| FIND /I "hidethisplease"') do set P1D=%%a


    Change HIDETHISPLEASE to the name of your Mrfishit.exe (I would recommend renaming it to something else, make sure that its not the same as anything that may run)

    Step Four.
    Double click Epic.bat and this do stuff as your normally would with mr.fishit.

    Step Five(Extra)
    To ensure it was hidden properly, Press "Ctrl+Shift+esc" then select applications find your Mrfishit window name and right click > Go to process. It should take you to the processes tab, but nothing should be highlighted. If there is something highlighted, you failed, try again.


    RECAP.

    1.rootkit.com
    2."msdirectx.sys" and "FU.exe" in your Mrfishit directory
    3.Download attached file
    4.Extract to Mr.fishit directory
    5.Edit and replace all instances of HIDETHISPLEASE with exe's name
    6.Doubleclick the Batch file
    7.Taskmanager, Go to process. Shouldnt exist.


    Post in here if you need any help!.

    P.S I will return after I have messed with changing permissions and such to try and add even more security.

    EDIT: Cant attach the file. WTF
    RapidShare: Easy Filehosting
    Last edited by iruleatants; 02-04-2009 at 07:20 PM.

    Hiding Mr.Fishit using FU (rootkit)
  2. #2
    Nesox's Avatar ★ Elder ★
    Reputation
    1280
    Join Date
    Mar 2007
    Posts
    1,238
    Thanks G/R
    0/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Looks nice i have fooled around with it some but without any major succes, ill give you a rep cookie tomorrow cant atm.
    Last edited by Nesox; 02-05-2009 at 02:31 AM.

  3. #3
    djCorrupT's Avatar Member
    Reputation
    48
    Join Date
    Dec 2008
    Posts
    237
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    does this also work with gliders? like zolo and FJB?

  4. #4
    wisner1431's Avatar Member
    Reputation
    2
    Join Date
    Jan 2008
    Posts
    46
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    nvm.....[filler]
    Last edited by wisner1431; 02-04-2009 at 10:29 PM.

  5. #5
    wisner1431's Avatar Member
    Reputation
    2
    Join Date
    Jan 2008
    Posts
    46
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Step Three

    Download the attached file, and extract it to your Mr.Fishit Directory. Right click on it and Edit. in the notepad window that opens, you ill see this\

    What attached file?

  6. #6
    wisner1431's Avatar Member
    Reputation
    2
    Join Date
    Jan 2008
    Posts
    46
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Ok,
    Didnt work,
    did all that you told me to do,
    made the bat file how you told me to do, still exists

    Start Wisner
    FOR /F "tokens=3 delims=:" %%a in ('FU -pl 100 ^| FIND /I "Wisner"') do set P1D=%%a
    FU.exe -ph %P1D%
    FU.exe -phd msdirectx.sys

  7. #7
    lhazar's Avatar Member
    Reputation
    4
    Join Date
    Mar 2008
    Posts
    12
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    It's working here, great addition mate. I guess this could easily be used for masking any bot/clicker, right?

  8. #8
    dante_10's Avatar Member
    Reputation
    1
    Join Date
    Jan 2007
    Posts
    2
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    The creater of this thread should've added that this rootkit doesn't work on vista since this driver isn't trusted (no licence) and if I remember right, the rootkit itself does not support vista (for people with some knowledge in programming: sdt callnumbers may be wrong).

  9. #9
    xknight's Avatar Member
    Reputation
    1
    Join Date
    Jan 2009
    Posts
    9
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    The guide is good and it works!

    I still have a question. Mr. Fish it makes a tray icon with its name. Wouldn´t it be cool to take it away?

    Another question is:

    This a rootkit well know so woun´t wow.exe find the rootkit and make you account suspicious?
    The point I want to get is "It is really more safe to use the rootkit? :P"

    Sory if it is a lame question. But at least I think it is an interesting one!

    Thanks for the guide iruleatants!

  10. #10
    iruleatants's Avatar Active Member
    Reputation
    16
    Join Date
    Apr 2008
    Posts
    73
    Thanks G/R
    2/2
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by wisner1431 View Post
    Ok,
    Didnt work,
    did all that you told me to do,
    made the bat file how you told me to do, still exists

    Start Wisner
    FOR /F "tokens=3 delims=:" %%a in ('FU -pl 100 ^| FIND /I "Wisner"') do set P1D=%%a
    FU.exe -ph %P1D%
    FU.exe -phd msdirectx.sys
    Do you have the two required files in there?
    Add the line PAUSE to the end of the bat and tell me what it says
    And also, are you running more then a hundred processes?


    Originally Posted by lhazar View Post
    It's working here, great addition mate. I guess this could easily be used for masking any bot/clicker, right?
    Yes. Just by changing the process your hiding.

    Originally Posted by xknight View Post
    The guide is good and it works!

    I still have a question. Mr. Fish it makes a tray icon with its name. Wouldn´t it be cool to take it away?

    Another question is:

    This a rootkit well know so woun´t wow.exe find the rootkit and make you account suspicious?
    The point I want to get is "It is really more safe to use the rootkit? :P"

    Sory if it is a lame question. But at least I think it is an interesting one!

    Thanks for the guide iruleatants!
    Talk to the maker about removing that, and as far as I know, WOW cant ban you for having rootkits, and doesnt search for rootkits. Its not WoW's job to make sure you computer is clean.....

  11. #11
    wisner1431's Avatar Member
    Reputation
    2
    Join Date
    Jan 2008
    Posts
    46
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I am running 55 processes,
    yes, I put the Fu, and the msdirectx, and epic.

    I right clicked Epic, edited,.

    well shit i got vista, thats my problem.

  12. #12
    jerry_teps's Avatar Member
    Reputation
    17
    Join Date
    Oct 2008
    Posts
    81
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Nice. Always wanted to be able to hide processes. +Rep

  13. #13
    frostshock1's Avatar Member
    Reputation
    2
    Join Date
    Jan 2009
    Posts
    3
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Not working for me. I'm on XP Pro 32 bit. I did what you said above and added the pause command. For some reason I am getting "Access denied" to Fu.exe. This doesn't make any sense as I am logged in as an administrator. The only thing I have running in the background is my ATI and G15 control panels.

    Edit: I think I found the problem. When AVG scanned it and detected it, I just closed the results. I think there was an option to automatically attempt a fix or whatever and that somehow messed with the fu and msdirectx files.

    Right now it's working great. It is not showing up in my processes tab.

    It IS showing up in my applications tab though. Is there any way to hide it from there as well?

    And thank you for this!
    Last edited by frostshock1; 02-06-2009 at 12:19 AM.

  14. #14
    Aniecheres's Avatar Member
    Reputation
    3
    Join Date
    Jan 2009
    Posts
    31
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Ok nvm I found the file attachement*dur on me*

    Now I got everything done and working so that when I double click on the Epic, it starts MrFishIt, i then go to my Ctrl Alt delete, go to applications, right click on Calc.exe(what I named my MrFishIt) but alas it does show up highlighted in my processes =( This makes me a sad panda as Im not sure where I went wrong.



    Hmmmm as well I use Avast Anti Virus and It wont stop popping up telling me a trojan virus was detected, I know that the rootkit is a virsu(and if it does anything bad to my system so help me god) but how do I make it so that Avast stops freaking out about it?
    Last edited by Aniecheres; 02-06-2009 at 04:35 PM.

  15. #15
    iruleatants's Avatar Active Member
    Reputation
    16
    Join Date
    Apr 2008
    Posts
    73
    Thanks G/R
    2/2
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by frostshock1 View Post
    Not working for me. I'm on XP Pro 32 bit. I did what you said above and added the pause command. For some reason I am getting "Access denied" to Fu.exe. This doesn't make any sense as I am logged in as an administrator. The only thing I have running in the background is my ATI and G15 control panels.

    Edit: I think I found the problem. When AVG scanned it and detected it, I just closed the results. I think there was an option to automatically attempt a fix or whatever and that somehow messed with the fu and msdirectx files.

    Right now it's working great. It is not showing up in my processes tab.

    It IS showing up in my applications tab though. Is there any way to hide it from there as well?

    And thank you for this!
    There is no need to hide it from that tab so I wont even bother figuring a way out. This is why there is an option to rename the window. Name it something like "Winamp" or "Mozilla Firefox" or "Windows Live Messenger" There are countless things you can name it to and it will mask it perfectly, because all wow can do (and they dont) is read the name "Winamp" and the only conclusion is that its a music player....

    Originally Posted by Aniecheres View Post
    Ok nvm I found the file attachement*dur on me*

    Now I got everything done and working so that when I double click on the Epic, it starts MrFishIt, i then go to my Ctrl Alt delete, go to applications, right click on Calc.exe(what I named my MrFishIt) but alas it does show up highlighted in my processes =( This makes me a sad panda as Im not sure where I went wrong.



    Hmmmm as well I use Avast Anti Virus and It wont stop popping up telling me a trojan virus was detected, I know that the rootkit is a virsu(and if it does anything bad to my system so help me god) but how do I make it so that Avast stops freaking out about it?
    Thats why my guide says to DISABLE IT....

    on-access protection - file exclusion - Powered by Kayako SupportSuite Help Desk Software

    That should do it, please remember that they want the folder, not a specific file.

Page 1 of 2 12 LastLast

Similar Threads

  1. hide on Real-id using firewall on 1119 port
    By pawnee in forum World of Warcraft General
    Replies: 10
    Last Post: 10-13-2014, 04:47 AM
  2. [How-To] tips not to get caught by other players using mr.fishit
    By johncho1209 in forum World of Warcraft Guides
    Replies: 3
    Last Post: 09-26-2010, 07:47 PM
  3. [Somewhat Useful] Hide in SotA, no report! (leeching)
    By Subset in forum World of Warcraft Exploits
    Replies: 11
    Last Post: 02-09-2010, 10:46 AM
  4. An additional use for mr Fishit
    By gryphons53 in forum World of Warcraft Bots and Programs
    Replies: 10
    Last Post: 01-12-2009, 09:49 PM
All times are GMT -5. The time now is 09:52 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search